[Shorewall-users] MultiISP balancing and ftps

2009-10-20 Thread Christian Vieser
Hi, I'm running a shorewall box with balancing over three ISPs and have two data transfers to customers via ftps. All went fine, but suddenly the ftp jobs didn't work any more. I discovered, that sometimes the ftps control session left the firewall on ISP 1 and the data session on ISP 2. So the

Re: [Shorewall-users] MultiISP balancing and ftps

2009-10-20 Thread Robert K Coffman Jr. -Info From Data Corp.
>Is there a "shorewall way" to solve this problem? I would start with http://www.shorewall.net/MultiISP.html. Sounds like the "track" option may solve this. - Bob Coffman -- Come build with us! The BlackBerry(R) Develo

Re: [Shorewall-users] MultiISP balancing and ftps

2009-10-20 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/20/2009 06:50 AM, Robert K Coffman Jr. -Info From Data Corp. wrote: >> Is there a "shorewall way" to solve this problem? > > I would start with http://www.shorewall.net/MultiISP.html. > > Sounds like the "track" option may solve this. I agree

Re: [Shorewall-users] MultiISP balancing and ftps

2009-10-21 Thread Christian Vieser
Tom wrote: >>> Is there a "shorewall way" to solve this problem? >> >> I would start with http://www.shorewall.net/MultiISP.html. >> Sounds like the "track" option may solve this. > > I agree that this is another case where 'track' should help. I'm sorry, but I found no hint in the MultiISP

Re: [Shorewall-users] MultiISP balancing and ftps

2009-10-21 Thread Tom Eastep
Christian Vieser wrote: > Tom wrote: > >>> Is there a "shorewall way" to solve this problem? > >> > >> I would start with http://www.shorewall.net/MultiISP.html. > >> Sounds like the "track" option may solve this. > > > > I agree that this is another case where 'track' should help. > > I'm s

Re: [Shorewall-users] MultiISP balancing and ftps

2009-10-21 Thread Tom Eastep
Tom Eastep wrote: > Christian Vieser wrote: >> So, the question is: When the first connection is established, how can I >> mark >> all further connections (from the origin of the connection or to the >> destination >> of the connection) to use the same provider, as long as the first >> connecti

Re: [Shorewall-users] MultiISP balancing and ftps

2009-10-21 Thread Christian Vieser
Tom Eastep wrote: > Try using the 'SAME' MARK/CLASSIFY target in a tcrule that specifies the > ftps client's address in the SOURCE column. Hi Tom, thank you very much for pointing me to the right direction. Although I run firewalls for a while now, I have no experience with the abilities of tcrule